3 ms·
This is nonsense. The self-signature on a root certificate is irrelevant unless you can easily calculate second pre-images, and that's not true even of MD5, and
by agl 9y ago
This is nonsense. The self-signature on a root certificate is irrelevant unless you can easily calculate second pre-images, and that's not true even of MD5, and accepting a root doesn't mean that the validator would accept that hash function on a non-root.
Equifax is only a 1024-bit RSA key, which isn't ideal, but it expires on Aug 22nd this year and the key-size of the root doesn't impact confidentiality.